2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41453MEDIUM4.8A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitr...
CVE-2024-39967MEDIUM6.5Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command...
CVE-2024-36751MEDIUM6.5An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL.
CVE-2024-48126CRITICAL9.8HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service...
CVE-2024-48125HIGH7.5An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via craft...
CVE-2024-48123HIGH8.4An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via u...
CVE-2024-48122MEDIUM6.7Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileg...
CVE-2024-48121MEDIUM6.5The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. Thi...
CVE-2024-54540MEDIUM4.3The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Proc...
CVE-2024-54535MEDIUM4.3A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia ...
CVE-2024-54470MEDIUM4.6A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPad...
CVE-2024-44136MEDIUM4.6This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...
CVE-2024-40854MEDIUM5.5A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS ...
CVE-2024-40839LOW2.4This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...
CVE-2024-40771HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and...
CVE-2024-27856HIGH7.8The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5...
CVE-2024-52005HIGH8.8Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messa...
CVE-2024-7085HIGH8.2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ S...
CVE-2024-57025MEDIUM6.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p...
CVE-2024-57024MEDIUM6.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute...
CVE-2024-57023MEDIUM6.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p...
CVE-2024-57022HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" ...
CVE-2024-57021HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" ...
CVE-2024-57020HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute...
CVE-2024-57019HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now